Terminal device login method and apparatus
By receiving environmental data from terminal devices, calculating multiple security factors, combining device identifiers and account data, dynamically adjusting weight coefficients, and employing multiple verification methods, the security issues of multiple device logins are resolved, achieving higher login and transaction security.
Patent Information
- Application Number
- CN202411491825.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-24
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2044-10-24
AI Technical Summary
In existing technologies, the security of logging in through multiple devices cannot be guaranteed, and there is a lack of effective solutions.
By receiving environmental data from terminal devices, multiple security factors are calculated, and login verification methods are determined based on these factors, including location information, network information, and device information. Combined with device identification and account data, the weight coefficients are dynamically adjusted, and multiple verification methods are used to improve security.
It improves the security of terminal device login and transaction security, adapts to changes in different environments and user behaviors, dynamically adjusts verification methods, and enhances the protection of user transactions.
Smart Images

Figure CN119109705B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of Internet technology, and in particular to a method and apparatus for logging into a terminal device. Background Technology
[0002] With the widespread use of the internet, users increasingly need to log in to their mobile banking accounts on multiple devices. However, currently, logging in from multiple devices all uses a single verification method, which compromises security.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This specification provides a terminal device login method and apparatus to address the problem of insufficient security in existing terminal device login methods.
[0005] This specification provides an embodiment of a terminal device login method, including:
[0006] The terminal device receives a login request; the login request includes environmental data; the environmental data is data related to the current environment of the terminal device; the environmental data includes: location information, network information, and device information.
[0007] When the terminal device is a slave device, a first security factor is calculated based on the location information and the specified location information set corresponding to the terminal device; the network type of the terminal device is determined based on the network information, and a second security factor is determined based on the network type; a third security factor is calculated based on the device information; and the login verification method of the terminal device is determined based on the first security factor, the second security factor, and the third security factor.
[0008] Interact with the terminal device according to the login verification method, and receive login verification data fed back by the terminal device;
[0009] The login verification data is verified, and if the verification is successful, the terminal device is confirmed to have logged in successfully.
[0010] In one embodiment, the login request also includes a device identifier and account data;
[0011] Accordingly, before determining the login verification method of the terminal device based on the environmental data of the terminal device, the method further includes:
[0012] The type of the terminal device is determined based on the device identifier and the account data; the type of the terminal device includes master devices and slave devices.
[0013] In one embodiment, determining the login verification method for the terminal device based on the first security factor, the second security factor, and the third security factor includes:
[0014] The login security and trustworthiness of the terminal device are calculated using the following formula:
[0015] P = ap1 + bp2 + cp3;
[0016] Based on the login security and trustworthiness, the login verification method of the terminal device is determined;
[0017] Wherein, P is the login security trustworthiness of the terminal device; a, b and c are weighting coefficients; p1 is the first security factor; p2 is the second security factor; and p3 is the third security factor.
[0018] In one embodiment, after determining that the terminal device has successfully logged in, the method further includes:
[0019] After the terminal device successfully logs in, environmental data and behavioral data of the terminal device are collected.
[0020] In one embodiment, the method further includes:
[0021] When the terminal device is the main device, the system interacts with the terminal device according to a preset login verification method to obtain login verification data fed back by the terminal device.
[0022] The login verification data is verified, and if the verification is successful, the terminal device is confirmed to have logged in successfully.
[0023] In one embodiment, the method further includes:
[0024] After the terminal device successfully logs in, a transaction request sent by the terminal device is received; the transaction request includes target transaction information.
[0025] Obtain the environmental data of the terminal device and the historical transaction data corresponding to the terminal device;
[0026] The transaction verification method of the terminal device is determined based on the target transaction information, the environmental data, and the historical transaction data.
[0027] The system interacts with the terminal device based on the transaction verification method, receives transaction verification data from the terminal device, verifies the transaction verification data, and executes the transaction corresponding to the transaction request if the verification is successful.
[0028] In one embodiment, determining the transaction verification method of the terminal device based on the target transaction information, the environmental data, and the historical transaction data includes:
[0029] The security and trustworthiness of the terminal device are determined based on the environmental data of the terminal device.
[0030] Based on the historical transaction data and the target transaction information, the transaction feasibility of the terminal device is determined;
[0031] The transaction verification method of the terminal device is determined based on the security and trustworthiness and transaction feasibility of the terminal device.
[0032] In one embodiment, the method further includes:
[0033] Receive a device type change request; the device type change request is used to change the terminal device from a slave device to a master device;
[0034] The security and trustworthiness of the terminal device are determined based on the environmental data and historical behavior data of the terminal device.
[0035] If the security and trustworthiness of the terminal device meets the preset conditions, the change verification method is determined based on the security and trustworthiness.
[0036] Based on the change verification method, the terminal device is interacted with to obtain change verification data;
[0037] The change verification data is verified. If the verification is successful, the device type of the terminal device is changed from slave device to master device.
[0038] In one embodiment, changing the device type of the terminal device from a slave device to a master device includes:
[0039] Change the device type of the master device corresponding to the terminal device to a slave device;
[0040] Change the device type of the terminal device to main device.
[0041] In one embodiment, the login verification method includes a combination of one or more of the following verification methods: SMS verification code login, biometric authentication login, uplink SMS login, and password login.
[0042] This specification also provides a terminal device login device, including:
[0043] A receiving module is used to receive a login request sent by a terminal device; the login request includes environmental data; the environmental data is data related to the current environment of the terminal device; the environmental data includes: location information, network information, and device information;
[0044] The determination module is configured to, when the terminal device is a slave device, calculate a first security factor based on the location information and a specified location information set corresponding to the terminal device; determine the network type of the terminal device based on the network information; determine a second security factor based on the network type; calculate a third security factor based on the device information; and determine the login verification method of the terminal device based on the first security factor, the second security factor, and the third security factor.
[0045] The interaction module is used to interact with the terminal device according to the login verification method and receive login verification data fed back by the terminal device;
[0046] The verification module is used to verify the login verification data, and if the verification is successful, it determines that the terminal device has successfully logged in.
[0047] In one embodiment, the apparatus further includes a transaction module, specifically configured to: after the terminal device successfully logs in, receive a transaction request sent by the terminal device; the transaction request includes a transaction amount; acquire environmental data of the terminal device and historical transaction data corresponding to the terminal device; determine a transaction verification method for the terminal device based on the transaction amount, the environmental data, and the historical transaction data; interact with the terminal device based on the transaction verification method and receive transaction verification data fed back by the terminal device; verify the transaction verification data, and if the verification is successful, execute the transaction corresponding to the transaction request.
[0048] In one embodiment, the apparatus further includes a change module, specifically configured to: receive a device type change request; the device type change request is used to change the terminal device from a slave device to a master device; determine the security and trustworthiness of the terminal device based on the terminal device's environmental data and historical behavior data; if the security and trustworthiness of the terminal device meets preset conditions, determine a change verification method based on the security and trustworthiness; interact with the terminal device based on the change verification method to obtain change verification data; verify the change verification data, and if the verification is successful, change the device type of the terminal device from a slave device to a master device.
[0049] This specification also provides a computer device, including a processor and a memory for storing processor-executable instructions, wherein the processor executes the instructions to implement the steps of the terminal device login method described in any of the above embodiments.
[0050] This specification also provides a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the steps of the terminal device login method described in any of the above embodiments.
[0051] This specification also provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the terminal device login method described in any of the above embodiments.
[0052] This specification provides a terminal device login method. A server can receive a login request from a terminal device. When the terminal device is a slave device, the server can determine the login verification method based on environmental data in the login request. Then, the server interacts with the terminal device according to the determined login verification method, enabling the slave device to log in using that method. Specifically, a first security factor can be calculated based on location information and a specified location information set corresponding to the terminal device. A second security factor can be determined based on network information, and a third security factor can be calculated based on device information. The login verification method is then determined based on the first, second, and third security factors. Combining multiple factors to determine the login verification method improves accuracy. This solution, when the terminal device is a slave device, determines the login verification method based on environmental data. It fully considers the environment of the terminal device during login verification, and by providing multiple verification methods, it improves the security of slave device login and protects user transaction security. Attached Figure Description
[0053] The accompanying drawings, which are included to provide a further understanding of this specification and form part of it, do not constitute a limitation thereof. In the drawings:
[0054] Figure 1 A schematic diagram illustrating an application scenario of a terminal device login method according to an embodiment of this specification is shown;
[0055] Figure 2 A flowchart of a terminal device login method according to an embodiment of this specification is shown;
[0056] Figure 3 A schematic diagram of a terminal device login device according to one embodiment of this specification is shown;
[0057] Figure 4 A schematic diagram of a computer device according to one embodiment of this specification is shown. Detailed Implementation
[0058] The principles and spirit of this specification will now be described with reference to several exemplary embodiments. It should be understood that these embodiments are given merely to enable those skilled in the art to better understand and implement this specification, and are not intended to limit the scope of this specification in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of this disclosure to those skilled in the art.
[0059] Those skilled in the art will recognize that the embodiments described in this specification can be implemented as a system, apparatus, method, or computer program product. Therefore, the disclosure of this specification can be specifically implemented in the following forms: entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.
[0060] It should be noted that the information and data related to users involved in the embodiments of this specification are all information and data authorized by the user or fully authorized by the relevant parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with relevant laws, regulations, and standards, and necessary confidentiality measures have been taken. They do not violate public order and good morals, and corresponding operation entry points are provided for users or relevant parties to choose to authorize or refuse.
[0061] It should also be noted that in the embodiments of this specification, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.
[0062] This specification provides an embodiment of a terminal device login method. Figure 1 This diagram illustrates an application scenario of a terminal device login method according to one embodiment of this specification. For example... Figure 1 As shown, a terminal device can send a login request to the server. The login request may include data related to the terminal device's current environment. When the terminal device is a slave device, the server can determine the login verification method based on the terminal device's current environment data. Then, the server and terminal device can interact according to the determined login verification method, and the server can receive the login verification data returned by the terminal device. The server can verify the login verification data, and if the verification is successful, the terminal device is considered to have successfully logged in. In other words, when the terminal device is a slave device, determining the login verification method based on the terminal device's environment data can improve the security of terminal device login.
[0063] Figure 2 A flowchart of a terminal device login method according to an embodiment of this specification is shown. Although this specification provides method operation steps or apparatus structures as shown in the following embodiments or figures, more or fewer operation steps or module units may be included in the method or apparatus based on conventional or non-inventive effort. In steps or structures where there is no logically necessary causal relationship, the execution order of these steps or the module structure of the apparatus is not limited to the execution order or module structure described in the embodiments and figures of this specification. When the method or module structure is applied in a practical device or terminal product, it can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment, or even a distributed processing environment) according to the method or module structure shown in the embodiments or figures.
[0064] Specifically, such as Figure 2 As shown, a terminal device login method provided in one embodiment of this specification may include the following steps.
[0065] Step S201: Receive a login request sent by a terminal device; the login request includes environmental data; the environmental data is data related to the current environment of the terminal device; the environmental data includes: location information, network information, and device information.
[0066] The method in this embodiment can be applied to a server. The server can be an online banking server, such as a mobile banking server. The server can receive login requests sent by terminal devices. Terminal devices can send login requests by entering an account number, mobile phone number, or ID card. The login request may include environmental data. The environmental data may be data related to the current environment of the terminal device.
[0067] In one embodiment, environmental data may include location information, network information, and device information. Location information may be the location data of the terminal device, such as the country, province, city, and district. Network information may be data such as the network type and network name currently used by the terminal device. Device information may be data such as the terminal device's operating system, device model, list of installed software, and whether root access has been obtained.
[0068] Step S202: If the terminal device is a slave device, calculate a first security factor based on the location information and the specified location information set corresponding to the terminal device; determine the network type of the terminal device based on the network information; determine a second security factor based on the network type; calculate a third security factor based on the device information; and determine the login verification method of the terminal device based on the first security factor, the second security factor, and the third security factor.
[0069] When the terminal device is a slave device, the login verification method can be determined based on the terminal device's environmental data. The terminal device can be either a master or slave device. Master and slave devices are two different types of devices corresponding to one account. The master device can be the terminal device logging in for the first time or a user-specified terminal device. The slave device can be any terminal device other than the master device. Master and slave devices have different permissions. The master device can have full permissions, while the slave device only has partial permissions.
[0070] In this embodiment, environmental data may include location information, network information, and device information. A first security factor can be calculated based on the location information of the terminal device and a specified location information set corresponding to the terminal device. The location information may be the location data of the terminal device, such as its country, province, city, and district. The specified location information set corresponding to the terminal device may be a set of the terminal device's permanent addresses. For example, if the location information of the terminal device exists in the specified location information set, the first security factor is determined to be a first value. If the location information of the terminal device does not exist in the specified location information set but is within a preset distance from the specified location information set, the first security factor is determined to be a second value. If the location information of the terminal device does not exist in the specified location information set and is not within a preset distance from the specified location information set, the first security factor is determined to be a third value. The first value is greater than the second value, and the second value is greater than the third value. A higher first security factor indicates higher security. It is understood that other methods can also be used to calculate the first security factor of the terminal device.
[0071] Network information can include data such as the network type and network name currently used by the terminal device. In one embodiment, the network type of the terminal device can be determined based on the network information. Network types can include: carrier traffic, home network, work network, and public network. A second security factor can then be determined based on the network type. In one embodiment, if the network type is carrier traffic, the second security factor is determined to be a first value. If the network type is a home network, the second security factor is determined to be a second value. If the network type is a work network, the second security factor is determined to be a third value. If the network type is a public network, the second security factor is determined to be a fourth value. The first value is greater than the second value, the second value is greater than the third value, and the third value is greater than the fourth value. It is understood that other methods can also be used to calculate the second security factor of the terminal device. For example, based on the network name and the set of network names corresponding to the terminal device, it can be determined whether the network the terminal device is on is a commonly used network; if so, the second security factor is high; otherwise, the second security factor is low.
[0072] A third security factor can be calculated based on the device information. Device information may include the terminal device's operating system, device model, installed software list, and whether root access has been obtained. For example, it can be determined whether risky software exists in the terminal device's installed software list. Risky software may include remote desktop software, software with fraud risks, etc. It can also be determined whether root access has been obtained. In one embodiment, if the terminal device does not have risky software installed and does not have root access, the third security factor of the terminal device is determined as a first value. If the terminal device has root access and does not have risky software installed, the third security factor of the terminal device is determined as a second value. If the terminal device does not have root access but has risky software installed, the third security factor of the terminal device is determined as a third value. If the terminal device has root access and has risky software installed, the third security factor of the terminal device is determined as a fourth value. The first value is greater than the second value, the second value is greater than the third value, and the third value is greater than the fourth value. It is understood that other methods can also be used to calculate the third security factor of the terminal device.
[0073] After calculating the first security factor, the second security factor, and the third security factor, the login verification method for the terminal device can be determined based on the first security factor, the second security factor, and the third security factor.
[0074] In some embodiments of this specification, the login request may further include a device identifier and account data. Correspondingly, before determining the login verification method of the terminal device based on the terminal device's environmental data, the method may further include: determining the type of the terminal device based on the device identifier and the account data; the type of the terminal device may include a master device and a slave device. In this embodiment, the login request may further include a device identifier and account data. The device identifier can be used to uniquely identify the terminal device. For example, the device identifier may be the device's UDID (Unique Device Identifier). The account data may be data that can be used to uniquely identify an account, such as a user's account, mobile phone number, username, or ID card number. After receiving the login request, the server can obtain the device identifier of the master device corresponding to the account data. Then, the device identifier of the terminal device can be compared with the device identifier of the corresponding master device. If they match, the device is a master device; otherwise, the device is a slave device. Through the above method, the device type of the terminal device can be determined.
[0075] In one embodiment, the security and trustworthiness of the terminal device can be determined based on its environmental data, and then the login verification method can be determined based on that security and trustworthiness. A higher security and trustworthiness value indicates a more secure and trustworthy terminal device. In one embodiment, the server can store the correspondence between the security and trustworthiness of the terminal device and the login verification method. For example, in one embodiment, if the security and trustworthiness is greater than a first preset trustworthiness, the login verification method is determined as the first login verification method; if the security and trustworthiness is greater than a second preset trustworthiness but not greater than the first preset trustworthiness, the login verification method is determined as the second login verification method; if the security and trustworthiness is not greater than the second preset trustworthiness, the login verification method is determined as the third login verification method. The first login verification method is the most lenient, and the third login verification method is the most stringent. By using this method, the security and trustworthiness of the terminal device can be determined first based on environmental data, and then the login verification method can be determined based on that security and trustworthiness, thus improving login security.
[0076] Step S203: Interact with the terminal device according to the login verification method and receive login verification data fed back by the terminal device.
[0077] Step S204: Verify the login verification data. If the verification is successful, determine that the terminal device has successfully logged in.
[0078] After determining the login verification method for the terminal device, interaction can be performed with the terminal device according to the login verification method, and the login verification data fed back by the terminal device can be received. For example, in one embodiment, the login verification method is password login. The server sends the login verification method to the client, the client displays a password input interface to the user, the user enters the password, the client feeds the password back to the server, and the server verifies the password.
[0079] The server verifies the received login verification data. If the verification is successful, the server can determine that the terminal device has successfully logged in.
[0080] In the above embodiments, the server can receive login requests sent by terminal devices. When the terminal device is a slave device, the server can determine the login verification method for the terminal device based on the environmental data in the login request. Then, the server interacts with the terminal device according to the determined login verification method, enabling the slave device to log in using that method. This solution, when the terminal device is a slave device, determines the login verification method based on environmental data. It fully considers the environment in which the terminal device is located during login verification. By providing multiple verification methods, it can improve the security of slave device logins and protect user transaction security.
[0081] In some embodiments of this specification, determining the login verification method of the terminal device based on the first security factor, the second security factor, and the third security factor may include calculating the login security trustworthiness of the terminal device according to the following formula:
[0082] P = ap1 + bp2 + cp3;
[0083] Based on the login security and trustworthiness, the login verification method of the terminal device is determined;
[0084] Where P represents the login security and trustworthiness of the terminal device; a, b, and c are weighting coefficients; p1 is the first security factor; p2 is the second security factor; and p3 is the third security factor. In this embodiment, different weights are set according to the actual situation, which can more accurately calculate the security and trustworthiness of the terminal device.
[0085] In some embodiments of this specification, the weighting coefficients a, b, and c can be dynamically adjusted.
[0086] In one embodiment, historical user data can be collected and analyzed, including device login frequency, financial transaction behavior, and geographic location changes. A time window approach is used to periodically update the weights. For example, the relative importance of factors can be calculated weekly or monthly, and the weights adjusted accordingly. Linear regression or logistic regression analysis can also be used to identify the importance of each factor in past events, and the weights adjusted accordingly.
[0087] In another embodiment, weight coefficients can be dynamically adjusted through online learning. Incremental learning can be used to deploy machine learning algorithms that automatically update the model as new data arrives, such as online random forests, which can update with new data without discarding previously learned knowledge. Naive Bayes is relatively simple and allows for rapid model updates. A real-time feedback mechanism dynamically adjusts factor weights based on the current verification results when a user makes a transaction or logs in. For example, if a factor frequently appears in erroneous logins, its weight can be increased.
[0088] In one embodiment, user behavior can be monitored in real time. If abnormal behavior is detected (such as frequent device changes, logging in from uncommon geographical locations, etc.), the weights of certain factors can be temporarily increased. User behavior can be clustered to identify patterns of normal and potentially abnormal behavior, and the scores and even weights of factors can be dynamically adjusted based on the clustering results.
[0089] In one embodiment, a reinforcement learning model can be used to learn and optimize during each user interaction. The model adjusts the weights through a reward mechanism (such as the success or failure of a user's action). The weights of the factors can be continuously updated by defining the state of each behavior, the action taken (choosing a verification method), and the reward received (whether the transaction was successful or safe).
[0090] In one embodiment, the user interface can allow users to provide feedback on the complexity of the verification method, and the system can adjust the weight of the factor based on the feedback. For example, if the user selects "This verification method is too cumbersome," the system will reduce the weight of that factor.
[0091] In one embodiment, A / B testing can be conducted with different weight settings to monitor user behavior and results, and analyze which set of weights can effectively improve security and user experience.
[0092] By employing various methods such as historical data analysis, online learning, anomaly detection, reinforcement learning, user feedback, and / or A / B testing, an adaptive mechanism can be formed, enabling the dynamic adjustment of security factor weights to adapt to constantly changing user behavior and the environment. This flexible system can enhance the ability to respond to potential risks while ensuring security and user experience.
[0093] In some embodiments of this specification, after confirming successful login of the terminal device, the method may further include: collecting environmental data and behavioral data of the terminal device. The environmental data may include the terminal device's location information, device information, and network information. Real-time collection of environmental and behavioral data after successful login can be used to subsequently assess the security and trustworthiness of the terminal device, facilitating the determination of transaction verification methods and device type changes.
[0094] In some embodiments of this specification, the method may further include: when the terminal device is the main device, interacting with the terminal device according to a preset login verification method to obtain login verification data fed back by the terminal device; verifying the login verification data, and determining that the terminal device has successfully logged in if the verification is successful.
[0095] In this embodiment, when the terminal device is the main device, the system can interact with the terminal device according to a preset login verification method to obtain login verification data from the terminal device. This login verification data is then verified, and if the verification is successful, the main device is confirmed to have logged in successfully. The login verification method for the main device can be a pre-set method, such as mobile phone verification code login, fingerprint recognition verification, or other login verification methods. Through the above method, a pre-set login verification method can be used for the main device's login verification.
[0096] In some embodiments of this specification, the method may further include: after the terminal device successfully logs in, receiving a transaction request sent by the terminal device; the transaction request may include target transaction information; obtaining environmental data of the terminal device and historical transaction data corresponding to the terminal device; determining a transaction verification method for the terminal device based on the target transaction information, the environmental data, and the historical transaction data; interacting with the terminal device based on the transaction verification method and receiving transaction verification data fed back by the terminal device; verifying the transaction verification data, and executing the transaction corresponding to the transaction request if the verification is successful.
[0097] In this embodiment, after successfully logging in on the terminal device, the user can perform transactions on the terminal device. Transactions may include transfers, payments, and purchasing financial products. The server can receive transaction requests sent by the terminal device. The transaction request may include target transaction information, such as transaction type, transaction amount, and information of both parties. The server can determine the transaction verification method for the terminal device based on the target transaction information, environmental data, and historical transaction data. This approach improves the security of transactions and ensures the safety of user assets.
[0098] In some embodiments of this specification, determining the transaction verification method of the terminal device based on the target transaction information, the environmental data, and the historical transaction data may include: determining the security and trustworthiness of the terminal device based on the environmental data of the terminal device; determining the transaction feasibility of the terminal device based on the historical transaction data and the target transaction information; and determining the transaction verification method of the terminal device based on the security and trustworthiness of the terminal device and the transaction feasibility.
[0099] In this embodiment, the environmental data may include the location information, device information, and network information of the terminal device. The server can determine the security and trustworthiness of the terminal device based on its environmental data. The specific method for determining the security and trustworthiness of the terminal device can be found in the determination method described in the preceding embodiments, and will not be repeated here.
[0100] The server can also determine a user's transaction behavior habits based on historical transaction data. Then, it can determine whether the target transaction information corresponding to the current transaction request matches the user's transaction behavior habits, and based on this, determine the transaction feasibility of the terminal device. For example, the more the terminal device's transaction request matches the user's transaction behavior habits, the higher the transaction feasibility; conversely, the less the terminal device's transaction request matches the user's transaction behavior habits, the lower the transaction feasibility. For instance, if the transaction frequency is close to the transaction frequency of a historical time period, it matches the transaction behavior habits. Similarly, if the transaction amount is close to the transaction amount of a historical time period, it matches the transaction behavior habits. Then, the server can determine the transaction verification method for the terminal device based on the terminal device's security credibility and transaction feasibility. In an exemplary embodiment, the product of security credibility and transaction feasibility can be calculated, and the transaction verification method can be determined based on this product. The larger the product, the more lenient the selected transaction verification method; the smaller the product, the more stringent the selected transaction method. It is understood that other methods can also be used to determine the transaction verification method for the terminal device. In this embodiment, the transaction verification method is determined by combining the security and trustworthiness of the terminal device and the feasibility of the transaction, which can further improve the security of transaction behavior and ensure the safety of users' property.
[0101] In some embodiments of this specification, when the security and trustworthiness of the terminal device and the feasibility of the transaction are both low, the server may prevent the client from performing transaction operations.
[0102] In some embodiments of this specification, the method may further include: receiving a device type change request; the device type change request being used to change the terminal device from a slave device to a master device; determining the security and trustworthiness of the terminal device based on the terminal device's environmental data and historical behavior data; if the security and trustworthiness of the terminal device meets preset conditions, determining a change verification method based on the security and trustworthiness; interacting with the terminal device based on the change verification method to obtain change verification data; verifying the change verification data, and if the verification is successful, changing the device type of the terminal device from a slave device to a master device.
[0103] In this embodiment, the server can also receive a device type change request. The device type change request is used to change the terminal device from a slave device to a master device. The server can determine the security and trustworthiness of the terminal device based on its environmental data and historical behavior data. Environmental data may include the terminal device's location information, device information, and network information, etc. Historical behavior data may include historical transaction data, which can also reflect the trustworthiness of the terminal device. For example, if historical transaction data shows that the transaction frequency and amount within a historical time period are within a normal range, the terminal device has high trustworthiness. If historical transaction data shows that the recent transaction frequency and amount do not conform to transaction behavior habits, the terminal device has low trustworthiness. The reliability of the slave device as a master device can be determined by combining the terminal device's environmental data and historical transaction data. Then, based on the terminal device's reliability, a change verification method is determined. Afterwards, verification can be performed according to the change verification method. If the verification is successful, the slave device is changed to a master device. The higher the reliability, the more lenient the change verification method; the lower the reliability, the more stringent the change verification method. Through the above method, the change request can be verified based on the reliability of the terminal device.
[0104] In some embodiments of this specification, changing the device type of the terminal device from a slave device to a master device may include: changing the device type of the master device corresponding to the terminal device to a slave device; or changing the device type of the terminal device to a master device. When changing from a slave device to a master device, the device type of the original master device of the account corresponding to the terminal device may be changed to a slave device. Then, the type of the terminal device is changed to a master device.
[0105] In some embodiments of this specification, the login verification method may include a combination of one or more of the following verification methods: SMS verification code login, biometric authentication login, uplink SMS login, and password login. The login verification method may be one of the above methods, or a combination of multiple of the above methods.
[0106] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. For details, please refer to the foregoing descriptions of the relevant processing embodiments; they will not be repeated here.
[0107] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0108] The above method will be described below with reference to a specific embodiment. However, it is worth noting that this specific embodiment is only for better illustration of this specification and does not constitute an improper limitation of this specification.
[0109] This embodiment provides a terminal device login method. In this specific embodiment, the user's first login is considered the primary device, and logins from other devices are considered secondary devices. The primary device requires login using a login password plus the user's mobile phone number. When a secondary device logs in, it uses different authentication methods based on the device environment, network environment, and account environment, mainly including SMS verification code login, password login, SMS login, facial recognition login, and mobile phone number authentication login. After logging in as a secondary device, if it needs to switch to the primary device, the intelligent system will decide on the authentication method. The primary device has the highest privileges, and the secondary device has partial privileges.
[0110] The main device login method is as follows.
[0111] Step 1. The user enters their mobile phone number, and the client system sends a login request to the server system. The main parameters transmitted are the user's mobile phone number, device information (operating system, device model, UDID, list of installed software, whether ROOT access has been obtained, etc.), network information (network type, carrier, signal strength, etc.), and geographical location.
[0112] Step 2. After receiving the client's request, the server system checks whether there are other logged-in devices using the mobile phone number and UDID. If it is the first time logging in, it responds to the client system's request.
[0113] Step 3. The client system receives the response from the server system. For first-time logins, the client system enters its local ID and login password to request login.
[0114] Step 4. Upon receiving the login request, if the verification is successful, the server system registers the master device relationship between the user and the device in this system and responds to the client system that the login was successful.
[0115] Step 5. During the use of the main device, the client system will continuously collect device information, network information, geographical location information, and user behavior information (such as querying transaction details, transferring funds, purchasing financial products, etc.).
[0116] The collected information is primarily used to dynamically calculate the security and trustworthiness of the current device, serving as a factor in the intelligent algorithm. When a user engages in financial activities on this device, such as transferring money, making payments, or purchasing funds, the system dynamically calculates the verification methods required for the user on this device based on the collected security factors. For example, if a user has made multiple transfers, payments, or purchased funds within the past year, considering their geographical location and network environment, the system algorithm determines that the user is secure and trustworthy in the current environment. Therefore, when conducting further financial transactions, the system can reduce the verification methods for this user's operation, such as requiring only SMS verification for transfers under 5000 yuan. Conversely, it can increase verification methods, such as facial recognition or mobile phone number authentication.
[0117] The following are the methods for logging in from the device.
[0118] Step 1. The user enters their mobile phone number, and the client system sends a login request to the server system. The main parameters transmitted are the user's mobile phone number, device information (operating system, device model, UDID, list of installed software, whether ROOT access has been obtained, etc.), network information (network type, carrier, signal strength, etc.), and geographical location.
[0119] Step 2. After receiving the client's request, the server system checks whether there are other login devices using the mobile phone number and UDID. If it is a slave device, the server system uses an intelligent algorithm to calculate the means of authentication required for the user on that device and responds to the client system's request.
[0120] When a device initiates a transfer request of 2000 yuan, the server system obtains the security factor from the request and compares it with the user's previously collected security factors and user behavior (such as recent transfer frequency, transfer amount, current transfer amount, recipient, etc.). Using intelligent algorithms with factor weighting, the system determines the verification methods required for this transfer request: SMS verification code + facial recognition. The server returns the calculation result to the client. Upon receiving the server's response, the client guides the user to perform the security verification and sends the user's verification result back to the server for verification. Once the server's verification is successful, the transfer is completed.
[0121] Step 3. The client system receives the response from the server system. If the device is a slave device, the client system will require the user to perform the corresponding login verification based on the server response.
[0122] Step 4. Upon receiving the login request, if the verification is successful, the server system registers the slave device relationship between the user and the device in this system and responds to the client system that the login was successful.
[0123] Step 5. During user operation, the system continuously collects device information, network information, geographical location information, user behavior information, etc., and adjusts the verification methods required by the business based on this information.
[0124] As mentioned earlier, this collected information is used to dynamically calculate the security and trustworthiness of the current device. When a user conducts a financial transaction, the system dynamically calculates the required verification methods, ensuring both the security of user funds and providing convenient and fast service. Another reason is that when a subordinate device applies to become the primary device, the system also dynamically calculates the required verification methods based on the aforementioned security factors to ensure the security of the permission change. For example, if a user has used a subordinate device for more than three months and has conducted multiple financial transactions with successful verification, the system considers the device relatively safe and reliable. When this device applies to become the primary device, the system assumes the application only requires SMS verification to succeed. Conversely, if additional verification methods are needed, such as facial recognition or device ID verification, the system will consider more robust verification methods.
[0125] The master-slave device change method is as follows.
[0126] Step 1. Master / Slave Device Change: The client system provides the function to change a slave device to a master device.
[0127] Go to a China Construction Bank branch, process the unbinding of the device at the counter, and then rebind it.
[0128] Step 2. When the user performs this operation, the client system sends a request to the server system, mainly transmitting parameters such as device information (operating system, device model, UDID, list of installed software, whether ROOT access has been obtained, etc.), network information (network type, carrier, signal strength, etc.), and geographical location.
[0129] Step 3. Upon receiving the request, the server system calculates the verification method using an intelligent algorithm and responds to the client system's request.
[0130] Step 4. The client system verifies the response method based on the server system's response requirements.
[0131] Step 5. The server system receives the change request from the client system. After successful verification, the slave device is changed to the master device, the original master device record is cleared, and the original device permissions are revoked.
[0132] Step 6. The master device has the highest privileges and can perform all permissions such as querying, transferring funds, investment and financial management, and payment. The slave device has partial permissions and can perform queries and small-amount transfers.
[0133] The above embodiments can distinguish between master and slave devices, which is more in line with current user habits. They can also differentiate device permissions, with master and slave devices having different permissions; the slave device only has partial permissions, providing services while ensuring user fund security. Different authentication methods are used for different device environments, network environments, and account environments, ensuring both security and speed.
[0134] Based on the same inventive concept, this specification also provides a terminal device login device in its embodiments, as described in the following embodiments. Since the principle by which the terminal device login device solves the problem is similar to that of the terminal device login method, the implementation of the terminal device login device can refer to the implementation of the terminal device login method, and repeated details will not be elaborated further. As used below, the terms "unit" or "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated. Figure 3 This is a structural block diagram of a terminal device login device according to an embodiment of this specification, such as... Figure 3 As shown, it includes: receiving module 301, determining module 302, interaction module 303 and verification module 304. The structure is described below.
[0135] The receiving module 301 is used to receive a login request sent by the terminal device; the login request includes environmental data; the environmental data is data related to the current environment of the terminal device.
[0136] The determining module 302 is used to determine the login verification method of the terminal device based on the environmental data of the terminal device when the terminal device is a slave device.
[0137] The interaction module 303 is used to interact with the terminal device according to the login verification method and receive login verification data fed back by the terminal device.
[0138] The verification module 304 is used to verify the login verification data, and if the verification is successful, it is determined that the terminal device has successfully logged in.
[0139] In some embodiments of this specification, the login request further includes a device identifier and account data; correspondingly, the receiving module is also configured to: determine the type of the terminal device based on the device identifier and the account data; the type of the terminal device includes a master device and a slave device.
[0140] In some embodiments of this specification, the environmental data includes: location information, network information, and device information; correspondingly, the determining module is specifically used to: calculate a first security factor based on the location information and a specified location information set corresponding to the terminal device; determine the network type of the terminal device based on the network information; determine a second security factor based on the network type; calculate a third security factor based on the device information; and determine the login verification method of the terminal device based on the first security factor, the second security factor, and the third security factor.
[0141] In some embodiments of this specification, the determining module is specifically used for:
[0142] The login security and trustworthiness of the terminal device are calculated using the following formula:
[0143] P = ap1 + bp2 + cp3;
[0144] Based on the login security and trustworthiness, the login verification method of the terminal device is determined;
[0145] Wherein, P is the login security trustworthiness of the terminal device; a, b and c are weighting coefficients; p1 is the first security factor; p2 is the second security factor; and p3 is the third security factor.
[0146] In some embodiments of this specification, the device further includes a data acquisition module, which is specifically used to: after determining that the terminal device has successfully logged in, collect environmental data of the terminal device and behavioral data of the terminal device.
[0147] In some embodiments of this specification, the device further includes a master device login module, which is specifically used to: when the terminal device is the master device, interact with the terminal device according to a preset login verification method to obtain login verification data fed back by the terminal device; verify the login verification data, and determine that the terminal device has successfully logged in if the verification is successful.
[0148] In some embodiments of this specification, the device further includes a transaction module, which is specifically used for: receiving a transaction request sent by the terminal device after the terminal device has successfully logged in; the transaction request includes a transaction amount; acquiring environmental data of the terminal device and historical transaction data corresponding to the terminal device; determining a transaction verification method for the terminal device based on the transaction amount, the environmental data, and the historical transaction data; interacting with the terminal device based on the transaction verification method and receiving transaction verification data fed back by the terminal device; verifying the transaction verification data, and executing the transaction corresponding to the transaction request if the verification is successful.
[0149] In some embodiments of this specification, the device further includes a change module, which is specifically configured to: receive a device type change request; the device type change request is used to change the terminal device from a slave device to a master device; determine the security and trustworthiness of the terminal device based on the environmental data and historical behavior data of the terminal device; if the security and trustworthiness of the terminal device meets preset conditions, determine a change verification method based on the security and trustworthiness; interact with the terminal device based on the change verification method to obtain change verification data; verify the change verification data, and if the verification is successful, change the device type of the terminal device from a slave device to a master device.
[0150] In some embodiments of this specification, the change module is specifically used to: change the device type of the master device corresponding to the terminal device to a slave device when the verification is successful; and change the device type of the terminal device to a master device.
[0151] In some embodiments of this specification, the login verification method includes a combination of one or more of the following verification methods: SMS verification code login, biometric authentication login, uplink SMS login, and password login.
[0152] As can be seen from the above description, the embodiments of this specification achieve the following technical effects: The server can receive login requests sent by terminal devices. When the terminal device is a slave device, it can determine the login verification method of the terminal device based on the environmental data in the login request, and then interact with the terminal device according to the determined login verification method, enabling the slave device to log in according to that login verification method. The above scheme, when the terminal device is a slave device, determines the login verification method based on environmental data. This fully considers the environment in which the terminal device is located during login verification. By providing multiple verification methods, it can improve the security of slave device login and protect the security of user transactions.
[0153] This specification also provides a computer device, which can be found in the following description. Figure 4The diagram shown illustrates the computer device structure based on the terminal device login method provided in the embodiments of this specification. Specifically, the computer device may include an input device 41, a processor 42, and a memory 43. The memory 43 stores processor-executable instructions. When the processor 42 executes the instructions, it implements the steps of the terminal device login method described in any of the above embodiments.
[0154] In this embodiment, the input device can specifically be one of the main devices for information exchange between the user and the computer system. The input device may include a keyboard, mouse, camera, scanner, light pen, handwriting input tablet, voice input device, etc.; the input device is used to input raw data and programs for processing these data into the computer. The input device can also receive data transmitted from other modules, units, and devices. The processor can be implemented in any suitable manner. For example, the processor can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers, etc. The memory can specifically be a memory device used to store information in modern information technology. The memory can include multiple layers; in digital systems, anything that can store binary data can be considered memory; in integrated circuits, a circuit without physical form but with storage function is also called memory, such as RAM, FIFO, etc.; in a system, a storage device with physical form is also called memory, such as a memory stick, TF card, etc.
[0155] In this embodiment, the specific functions and effects implemented by the computer device can be explained in comparison with other embodiments, and will not be repeated here.
[0156] This specification also provides a computer storage medium based on a terminal device login method, wherein the computer storage medium stores computer program instructions that, when executed by a processor, implement the steps of the terminal device login method described in any of the above embodiments.
[0157] In this embodiment, the storage medium includes, but is not limited to, Random Access Memory (RAM), Read-Only Memory (ROM), cache, hard disk drive (HDD), or memory card. The memory can be used to store computer program instructions. The network communication unit can be an interface configured according to standards specified in the communication protocol for network connection communication.
[0158] In this embodiment, the specific functions and effects implemented by the program instructions stored in the computer storage medium can be explained by comparison with other embodiments, and will not be repeated here.
[0159] This specification also provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the terminal device login method described in any of the above embodiments.
[0160] Obviously, those skilled in the art will understand that the modules or steps of the embodiments described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the embodiments of this specification are not limited to any particular combination of hardware and software.
[0161] It should be understood that the above description is for illustrative purposes and not for limitation. Many embodiments and applications beyond the provided examples will be apparent to those skilled in the art upon reading the above description. Therefore, the scope of this specification should not be determined by reference to the above description, but rather by reference to the foregoing claims and the full scope of their equivalents.
[0162] The above description is merely a preferred embodiment of this specification and is not intended to limit this specification. Various modifications and variations can be made to the embodiments described herein by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of protection of this specification.
Claims
1. A terminal device login method, characterized in that, include: Receive login requests sent by terminal devices; The login request includes environmental data; The environmental data refers to data related to the current environment of the terminal device. The environmental data includes: location information, network information, and device information; the login request also includes device identifier and account data. The type of the terminal device is determined based on the device identifier and the account data; the type of the terminal device includes master devices and slave devices. When the terminal device is a slave device, a first security factor is calculated based on the location information and the specified location information set corresponding to the terminal device; the network type of the terminal device is determined based on the network information, and a second security factor is determined based on the network type; a third security factor is calculated based on the device information; and the login verification method of the terminal device is determined based on the first security factor, the second security factor, and the third security factor. Interact with the terminal device according to the login verification method, and receive login verification data fed back by the terminal device; The login verification data is verified, and if the verification is successful, the terminal device is determined to have logged in successfully. The method further includes: when the terminal device is the main device, interacting with the terminal device according to a preset login verification method to obtain login verification data fed back by the terminal device; verifying the login verification data, and determining that the terminal device has successfully logged in if the verification is successful.
2. The terminal device login method according to claim 1, characterized in that, Based on the first security factor, the second security factor, and the third security factor, the login verification method for the terminal device is determined, including: The login security and trustworthiness of the terminal device are calculated using the following formula: P = ap1 + bp2 + cp3; Based on the login security and trustworthiness, the login verification method of the terminal device is determined; Wherein, P is the login security trustworthiness of the terminal device; a, b and c are weighting coefficients; p1 is the first security factor; p2 is the second security factor; and p3 is the third security factor.
3. The terminal device login method according to claim 1, characterized in that, After confirming that the terminal device has successfully logged in, the process also includes: After the terminal device successfully logs in, environmental data and behavioral data of the terminal device are collected.
4. The terminal device login method according to claim 1, characterized in that, Also includes: After the terminal device successfully logs in, a transaction request sent by the terminal device is received; the transaction request includes target transaction information. Obtain the environmental data of the terminal device and the historical transaction data corresponding to the terminal device; The transaction verification method of the terminal device is determined based on the target transaction information, the environmental data, and the historical transaction data. The system interacts with the terminal device based on the transaction verification method, receives transaction verification data from the terminal device, verifies the transaction verification data, and executes the transaction corresponding to the transaction request if the verification is successful.
5. The terminal device login method according to claim 4, characterized in that, Based on the target transaction information, the environmental data, and the historical transaction data, the transaction verification method of the terminal device is determined, including: The security and trustworthiness of the terminal device are determined based on the environmental data of the terminal device. Based on the historical transaction data and the target transaction information, the transaction feasibility of the terminal device is determined; The transaction verification method of the terminal device is determined based on the security and trustworthiness and transaction feasibility of the terminal device.
6. The terminal device login method according to claim 1, characterized in that, Also includes: Receive a device type change request; the device type change request is used to change the terminal device from a slave device to a master device; The security and trustworthiness of the terminal device are determined based on the environmental data and historical behavior data of the terminal device. If the security and trustworthiness of the terminal device meets the preset conditions, the change verification method is determined based on the security and trustworthiness. Based on the change verification method, the terminal device is interacted with to obtain change verification data; The change verification data is verified. If the verification is successful, the device type of the terminal device is changed from slave device to master device.
7. The terminal device login method according to claim 6, characterized in that, Changing the device type of the terminal device from slave device to master device includes: Change the device type of the master device corresponding to the terminal device to a slave device; Change the device type of the terminal device to main device.
8. The terminal device login method according to claim 1, characterized in that, The login verification method includes a combination of one or more of the following verification methods: SMS verification code login, biometric authentication login, uplink SMS login, and password login.
9. A terminal device login device, characterized in that, include: The receiving module is used to receive login requests sent by terminal devices; The login request includes environmental data; The environmental data refers to data related to the current environment of the terminal device; the environmental data includes: location information, network information, and device information; the login request also includes device identifier and account data; the receiving module is further configured to determine the type of the terminal device based on the device identifier and the account data; the type of the terminal device includes master device and slave device; The determination module is configured to, when the terminal device is a slave device, calculate a first security factor based on the location information and a specified location information set corresponding to the terminal device; determine the network type of the terminal device based on the network information; determine a second security factor based on the network type; calculate a third security factor based on the device information; and determine the login verification method of the terminal device based on the first security factor, the second security factor, and the third security factor. The interaction module is used to interact with the terminal device according to the login verification method and receive login verification data fed back by the terminal device; The verification module is used to verify the login verification data, and if the verification is successful, it determines that the terminal device has successfully logged in; The device further includes a master device login module, which is specifically used to: when the terminal device is the master device, interact with the terminal device according to a preset login verification method to obtain login verification data fed back by the terminal device; verify the login verification data, and determine that the terminal device has successfully logged in if the verification is successful.
10. The terminal device login device according to claim 9, characterized in that, Also includes: The transaction module is specifically configured to: receive a transaction request sent by the terminal device after the terminal device has successfully logged in; the transaction request includes a transaction amount; obtain the environmental data of the terminal device and the corresponding historical transaction data of the terminal device; determine the transaction verification method of the terminal device based on the transaction amount, the environmental data, and the historical transaction data; interact with the terminal device based on the transaction verification method and receive transaction verification data fed back by the terminal device; verify the transaction verification data, and if the verification is successful, execute the transaction corresponding to the transaction request.
11. A computer device, characterized in that, It includes a processor and a memory for storing processor-executable instructions, wherein the processor, when executing the instructions, implements the steps of the method according to any one of claims 1 to 8.
12. A computer-readable storage medium storing computer instructions thereon, characterized in that, When the instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 8.
13. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Account verification method and device
CN107248995A
Login verification method and device, electronic equipment and computer program product
CN118433710A